VDB
BIT-java-min-2024-25062
BIT-java-min-2024-25062
PUBLISHED
CVSS 7.5 HIGH
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
Risk Scores
CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | java-min | 0, 1.9.0, 0 |
Timeline
- May 6, 2026 CVE Published
- May 8, 2026 CVE Updated
References
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/604 url
- https://gitlab.gnome.org/GNOME/libxml2/-/tags url
- https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html url
- https://nvd.nist.gov/vuln/detail/CVE-2024-25062 url
- https://openjdk.org/groups/vulnerability/advisories/2024-10-15 url
- https://security.netapp.com/advisory/ntap-20241018-0009/ url
- https://www.oracle.com/security-alerts/cpuoct2024.html url